> managing changes to the policy and having a reporting endpoint that gives you insights into what is being violated is still difficult.
Is this targeting management at companies with multiple products? As a developer I just use Django Middleware to add this line to all our responses and call it a day:
response['Content-Security-Policy'] = "default-src 'none'"
(Well, we still sanitize all our inputs and have the headers to block XSS reflection, but there's still not much complexity.)